INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Zimbra Server Breach Exploited Vulnerability
| 2026-08-25 12:04 CRITICAL HIGH DATA BREACH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Zimbra Collaboration Suite, a widely used email and collaboration platform, has been compromised by threat actors exploiting a previously unknown vulnerability. This critical incident highlights the importance of timely patching and security awareness among organizations using this software. The flaw, CVE-2026-73570, allows attackers to execute code remotely, making it essential for companies to update their systems as soon as possible. Organizations must take immediate action to secure their Zimbra instances and prevent further exploitation by threat actors.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation to prevent command injection attacks, such as using parameterized queries or validating user input before executing it.
* Regularly update and patch Zimbra instances to ensure that known vulnerabilities are addressed, including the CVE-2026-73570 flaw mentioned in the articles.
* Configure SNMP notifications to be disabled on non-production systems to reduce the attack surface for unauthenticated attackers.
* Monitor logs for suspicious activity, such as unexpected service restarts or unusual file creations, and take action if necessary to prevent exploitation of the vulnerability.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
zi•••••.log
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT29APT29APT28APT28Winter VivernWinter Vivern
CVE-2025-66376CVE-2025-66376
CVE-2026-73570CVE-2026-73570
Target & Sectors
EUROPE
EUROPE
governmentgovernment
Incident Timeline
February 2023
Russian Winter Vivern exploited a reflected XSS flaw in Zimbra webmail portals to steal emails from NATO-aligned organizations.
Click on any entity below to view its context and source!
source_region
Russian Federation
Russian espionage group
Winter Vivern
exploited a reflected XSS flaw in February 2023 to steal emails from NATO-aligned organizations through Zimbra webmail portals.
For instance, Russian Winter Vivern cyber spies used a reflected XSS exploit in February 2023
to steal emails
belonging to NATO-aligned individuals and organizations from Zimbra webmail portals.
threat_actor
Winter Vivern
Russian espionage group
Winter Vivern
exploited a reflected XSS flaw in February 2023 to steal emails from NATO-aligned organizations through Zimbra webmail portals.
For instance, Russian Winter Vivern cyber spies used a reflected XSS exploit in February 2023
to steal emails
belonging to NATO-aligned individuals and organizations from Zimbra webmail portals.
organisation
NATO
Russian espionage group
Winter Vivern
exploited a reflected XSS flaw in February 2023 to steal emails from NATO-aligned organizations through Zimbra webmail portals.
For instance, Russian Winter Vivern cyber spies used a reflected XSS exploit in February 2023
to steal emails
belonging to NATO-aligned individuals and organizations from Zimbra webmail portals.
tactic
Espionage
Russian espionage group
Winter Vivern
exploited a reflected XSS flaw in February 2023 to steal emails from NATO-aligned organizations through Zimbra webmail portals.
October 2024
APT29 hackers exploited a security issue in the Zimbra Collaboration Suite to steal email account credentials.
Click on any entity below to view its context and source!
source_region
Russian Federation
U.S. and UK cyber agencies also warned in October 2024 that Russian Foreign Intelligence Service hackers (tracked as APT29, Midnight Blizzard, and Cozy Bear)
compromised Zimbra servers
using a ZCS flaw previously exploited to
steal email account credentials
.
In October 2024, U.S. and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear) linked to Russia's Foreign Intelligence Service were
targeting Zimbra servers
using a flaw previously exploited to
steal email account credentials
.
In October 2024, US and UK agencies warned that
APT29
, linked to Russia’s Foreign Intelligence Service, was targeting vulnerable Zimbra servers via a credential-stealing flaw.
In October 2024, US and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear and linked to Russia's Foreign Intelligence Service) were
targeting vulnerable Zimbra servers
by exploiting a security issue previously abused
to steal email account credentials
.
source_region
United Kingdom
U.S. and UK cyber agencies also warned in October 2024 that Russian Foreign Intelligence Service hackers (tracked as APT29, Midnight Blizzard, and Cozy Bear)
compromised Zimbra servers
using a ZCS flaw previously exploited to
steal email account credentials
.
In October 2024, U.S. and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear) linked to Russia's Foreign Intelligence Service were
targeting Zimbra servers
using a flaw previously exploited to
steal email account credentials
.
In October 2024, US and UK agencies warned that
APT29
, linked to Russia’s Foreign Intelligence Service, was targeting vulnerable Zimbra servers via a credential-stealing flaw.
In October 2024, US and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear and linked to Russia's Foreign Intelligence Service) were
targeting vulnerable Zimbra servers
by exploiting a security issue previously abused
to steal email account credentials
.
attribution
Russian Foreign Intelligence Service
U.S. and UK cyber agencies also warned in October 2024 that Russian Foreign Intelligence Service hackers (tracked as APT29, Midnight Blizzard, and Cozy Bear)
compromised Zimbra servers
using a ZCS flaw previously exploited to
steal email account credentials
.
threat_actor
APT29
U.S. and UK cyber agencies also warned in October 2024 that Russian Foreign Intelligence Service hackers (tracked as APT29, Midnight Blizzard, and Cozy Bear)
compromised Zimbra servers
using a ZCS flaw previously exploited to
steal email account credentials
.
In October 2024, U.S. and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear) linked to Russia's Foreign Intelligence Service were
targeting Zimbra servers
using a flaw previously exploited to
steal email account credentials
.
In October 2024, US and UK agencies warned that
APT29
, linked to Russia’s Foreign Intelligence Service, was targeting vulnerable Zimbra servers via a credential-stealing flaw.
In October 2024, US and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear and linked to Russia's Foreign Intelligence Service) were
targeting vulnerable Zimbra servers
by exploiting a security issue previously abused
to steal email account credentials
.
attribution
Foreign Intelligence Service
In October 2024, U.S. and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear) linked to Russia's Foreign Intelligence Service were
targeting Zimbra servers
using a flaw previously exploited to
steal email account credentials
.
In October 2024, US and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear and linked to Russia's Foreign Intelligence Service) were
targeting vulnerable Zimbra servers
by exploiting a security issue previously abused
to steal email account credentials
.
source_region
United States
In October 2024, US and UK agencies warned that
APT29
, linked to Russia’s Foreign Intelligence Service, was targeting vulnerable Zimbra servers via a credential-stealing flaw.
In October 2024, US and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear and linked to Russia's Foreign Intelligence Service) were
targeting vulnerable Zimbra servers
by exploiting a security issue previously abused
to steal email account credentials
.
at least July 2025
Threat actors used a phishing campaign to target Zimbra mail servers belonging to Western government and commercial organizations.
Click on any entity below to view its context and source!
source_region
Russian Federation
Last month, the U.S. government
disclosed
details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
industry
Government
Last month, the U.S. government
disclosed
details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
tactic
Phishing
Last month, the U.S. government
disclosed
details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
attribution
Laundry Bear
Last month, the U.S. government
disclosed
details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
attribution
CL-STA-1114
Last month, the U.S. government
disclosed
details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
March 2026
Russian military intelligence exploited a stored XSS vulnerability in Zimbra deployments.
Click on any entity below to view its context and source!
source_region
Russian Federation
Most recently, in March 2026, Seqrite Labs researchers documented APT28, tied to Russian military intelligence, exploiting a stored XSS vulnerability against Ukrainian government Zimbra deployments.
industry
Government
Most recently, in March 2026, Seqrite Labs researchers documented APT28, tied to Russian military intelligence, exploiting a stored XSS vulnerability against Ukrainian government Zimbra deployments.
threat_actor
APT28
Most recently, in March 2026, Seqrite Labs researchers documented APT28, tied to Russian military intelligence, exploiting a stored XSS vulnerability against Ukrainian government Zimbra deployments.
source_region
Ukraine
Most recently, in March 2026, Seqrite Labs researchers documented APT28, tied to Russian military intelligence, exploiting a stored XSS vulnerability against Ukrainian government Zimbra deployments.
July 20
The Zimbra security team released version 10.1.20 on July 20 to patch the CVE-2026-73570 vulnerability, which allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-73570
Synacor patched the security flaw (tracked as
CVE-2026-73570
), which allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, with the release of
ZCS version 10.1.20
on July 20.
The Zimbra security team patched the security flaw (tracked as
CVE-2026-73570
) in
version 10.1.20
, released on July 20.
Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20.
The Zimbra security team
released version 10.1.20
on July 20 to patch the vulnerability (tracked as
CVE-2026-73570
), which allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
infrastructure
10.1.20
Synacor patched the security flaw (tracked as
CVE-2026-73570
), which allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, with the release of
ZCS version 10.1.20
on July 20.
The Zimbra security team patched the security flaw (tracked as
CVE-2026-73570
) in
version 10.1.20
, released on July 20.
The Zimbra security team
released version 10.1.20
on July 20 to patch the vulnerability (tracked as
CVE-2026-73570
), which allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
organisation
Synacor
Synacor patched the security flaw (tracked as
CVE-2026-73570
), which allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, with the release of
ZCS version 10.1.20
on July 20.
attribution
CERT Polska
Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20.
target_region
Poland
Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20.
tactic
Remote Code Execution
The Zimbra security team
released version 10.1.20
on July 20 to patch the vulnerability (tracked as
CVE-2026-73570
), which allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
20 July 2026
Zimbra released version 10.1.20 on July 20, 2026, to address the exploit vulnerability.
Click on any entity below to view its context and source!
infrastructure
10.1.20
Zimbra released version 10.1.20 on 20 July 2026 to address the issue.
2026/07/21
Threat actors used a Russia-linked adversary's phishing campaign to target Zimbra mail servers.
Click on any entity below to view its context and source!
source_region
Russian Federation
Last month, the U.S. government
disclosed
details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
industry
Government
Last month, the U.S. government
disclosed
details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
tactic
Phishing
Last month, the U.S. government
disclosed
details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
attribution
Laundry Bear
Last month, the U.S. government
disclosed
details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
attribution
CL-STA-1114
Last month, the U.S. government
disclosed
details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.
infrastructure
10.1.20
"
The security issue was
patched
by Zimbra last month with the release of version 10.1.20.
Aug 20, 2026
Threat actors exploited a known vulnerability in the Zimbra Collaboration Suite to gain unauthorized access to affected systems.
2026/08/22
The 274 compromised instances were targeted by Shadowserver on August 22, 2026.
Click on any entity below to view its context and source!
general_metric
274 instances
274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22,"
Shadowserver warned
.
August 24
Zimbra Collaboration Suite servers were exposed online by Shadowserver due to a known exploit vulnerability.
Click on any entity below to view its context and source!
attribution
KEV
The Cybersecurity and Infrastructure Security Agency (CISA) also
added the flaw
to its
KEV catalog
following CERT Polska's warning and
ordered
U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days, by August 24.
Zimbra Collaboration Suite servers exposed online (Shadowserver)
On Friday, CISA confirmed CERT Polska's alert,
added the flaw
to its
KEV catalog,
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems within three days, by August 24.
attribution
CERT Polska's
The Cybersecurity and Infrastructure Security Agency (CISA) also
added the flaw
to its
KEV catalog
following CERT Polska's warning and
ordered
U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days, by August 24.
Zimbra Collaboration Suite servers exposed online (Shadowserver)
On Friday, CISA confirmed CERT Polska's alert,
added the flaw
to its
KEV catalog,
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems within three days, by August 24.
attribution
FCEB
The Cybersecurity and Infrastructure Security Agency (CISA) also
added the flaw
to its
KEV catalog
following CERT Polska's warning and
ordered
U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days, by August 24.
Zimbra Collaboration Suite servers exposed online (Shadowserver)
On Friday, CISA confirmed CERT Polska's alert,
added the flaw
to its
KEV catalog,
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems within three days, by August 24.
attribution
CISA
Zimbra Collaboration Suite servers exposed online (Shadowserver)
On Friday, CISA confirmed CERT Polska's alert,
added the flaw
to its
KEV catalog,
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems within three days, by August 24.
attribution
U.S. Federal Civilian Executive Branch
Zimbra Collaboration Suite servers exposed online (Shadowserver)
On Friday, CISA confirmed CERT Polska's alert,
added the flaw
to its
KEV catalog,
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems within three days, by August 24.
August 24, 2026
Threat actors exploited a known vulnerability in the Zimbra Collaboration Suite.
2026/08/25
Threat actors are exploiting CVE-2026-73570 in attacks on Zimbra Collaboration Suite (ZCS) servers.
Click on any entity below to view its context and source!
threat_actor
APT28
Most recently, in March, Seqrite Labs researchers spotted APT28 Russian military intelligence hackers abusing a stored cross-site scripting (XSS) Zimbra vulnerability
to breach Ukrainian government servers
.
Most recently, Seqrite Labs researchers revealed in March that APT28 (a state-sponsored threat group linked to Russia's military intelligence service) was exploiting a stored cross-site scripting (XSS) vulnerability
in attacks targeting Ukrainian government ZCS servers
.
More recently, in March, Seqrite Labs researchers also revealed that APT28 hackers (a state-backed threat group linked to Russia's military intelligence service) were exploiting a stored cross-site scripting (XSS) vulnerability
in attacks targeting Ukrainian government ZCS servers
.
threat_actor
Winter Vivern
Russian Winter Vivern cyber spies also
exploited a reflected Cross-Site Scripting (XSS) vulnerability
to steal emails
from
NATO-aligned email accounts in attacks targeting Zimbra webmail portals.
Russian Winter Vivern cyber spies have also abused a reflected Cross-Site Scripting (XSS) vulnerability
to steal emails
belonging to NATO-aligned individuals and organizations via Zimbra webmail portals.
organisation
Cross-Site Scripting
Russian Winter Vivern cyber spies also
exploited a reflected Cross-Site Scripting (XSS) vulnerability
to steal emails
from
NATO-aligned email accounts in attacks targeting Zimbra webmail portals.
Russian Winter Vivern cyber spies have also abused a reflected Cross-Site Scripting (XSS) vulnerability
to steal emails
belonging to NATO-aligned individuals and organizations via Zimbra webmail portals.
organisation
NATO
Russian Winter Vivern cyber spies also
exploited a reflected Cross-Site Scripting (XSS) vulnerability
to steal emails
from
NATO-aligned email accounts in attacks targeting Zimbra webmail portals.
Russian Winter Vivern cyber spies have also abused a reflected Cross-Site Scripting (XSS) vulnerability
to steal emails
belonging to NATO-aligned individuals and organizations via Zimbra webmail portals.
organisation
ZCS
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.
data_breach
270 Zimbra instances
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.
organisation
Zimbra Collaboration (
"A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed, and SNMP notifications are enabled," according to a description of the flaw in the NIST National Vulnerability Database (NVD).
organisation
the NIST National Vulnerability Database
"A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed, and SNMP notifications are enabled," according to a description of the flaw in the NIST National Vulnerability Database (NVD).
organisation
NVD
"A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed, and SNMP notifications are enabled," according to a description of the flaw in the NIST National Vulnerability Database (NVD).
organisation
CVE-2026
Map of compromised Zimbra instances (Shadowserver)
"Zimbra compromises associated with CVE-2026-73570 exploitation are spreading.
However, there is no information on how many of them are honeypots or have already been patched against the CVE-2026-73570 security flaw.
infrastructure
12,000 Zimbra servers
While threat security watchdog Shadowserver tracks
more than 12,000 Zimbra servers
exposed on the Internet, there is no information on how many are honeypots or have already been secured against attacks exploiting the CVE-2026-73570 flaw.
organisation
CVE-2026-73570
CVE-2026-73570 is especially risky because attackers can exploit it without authentication, the vulnerable service is enabled by default, and many Zimbra servers are exposed online.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
infrastructure
270 Zimbra servers
Hackers breached over 270 Zimbra servers in ongoing attacks.
organisation
SMTP
"Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user," it explained.
"Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
organisation
SNMP
The vulnerability affects systems with SNMP trap notifications enabled and the swatchdog service running, which is enabled by default.
infrastructure
12,100 Zimbra servers
Shadowserver
currently tracks
over 12,100 Zimbra servers reachable from the Internet, split roughly between Europe (4,382) and Asia (4,492).
Internet security watchdog Shadowserver now tracks
over 12,100 Zimbra servers
exposed online, most of them in Europe (4,382) and Asia (4,492).
financial
4,382 Europe
Shadowserver
currently tracks
over 12,100 Zimbra servers reachable from the Internet, split roughly between Europe (4,382) and Asia (4,492).
Internet security watchdog Shadowserver now tracks
over 12,100 Zimbra servers
exposed online, most of them in Europe (4,382) and Asia (4,492).
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Zimbra Collaboration Suite)
organisation
ZimReaper
The campaign was found to have weaponized CVE-2025-66376, a stored cross-site scripting vulnerability in Zimbra's Classic UI, to deliver a malicious JavaScript payload dubbed ZimReaper to harvest email communications and other sensitive data.
Tactical Metrics
Metrics
data_breach
270
Zimbra Instances
Click for context!
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.
Metrics
infrastructure
10.1.20
Software Version
…6-73570
), which allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, with the release of
ZCS version 10.1.20
on July 20.
The Zimbra security team patched the security flaw (tracked as
CVE-2026-73570
) in
version 10.1.20
, released on July 20.
Zimbra released version 10.1.20 on 20 July 2026 to address the issue.
"
The security issue was
patched
by Zimbra last month with the release of version 10.1.20.
The Zimbra security team
released version 10.1.20
on July 20 to patch the vulnerability (tracked as
CVE-2026-73570
), which allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP mon…
Metrics
infrastructure
270
Zimbra Servers
Hackers breached over 270 Zimbra servers in ongoing attacks.
Metrics
infrastructure
12,000
Zimbra Servers
While threat security watchdog Shadowserver tracks
more than 12,000 Zimbra servers
exposed on the Internet, there is no information on how many are honeypots or have already been secured against attacks exploiting the CVE-2026-73570 flaw.
Metrics
infrastructure
12,100
Zimbra Servers
Shadowserver
currently tracks
over 12,100 Zimbra servers reachable from the Internet, split roughly between Europe (4,382) and Asia (4,492).
Internet security watchdog Shadowserver now tracks
over 12,100 Zimbra servers
exposed online, most of them in Europe (4,382) and Asia (4,492).
Metrics
financial
4,382
Europe
Shadowserver
currently tracks
over 12,100 Zimbra servers reachable from the Internet, split roughly between Europe (4,382) and Asia (4,492).
Internet security watchdog Shadowserver now tracks
over 12,100 Zimbra servers
exposed online, most of them in Europe (4,382) and Asia (4,492).
Intelligence Sources
BleepingComputer
2026-08-25
Hackers breached over 270 Zimbra servers in ongoing attacks
BleepingComputer
Security Affairs
2026-08-22
BleepingComputer
2026-08-20
Critical Zimbra RCE flaw now actively exploited in attacks
BleepingComputer
BleepingComputer
2026-08-24
CISA orders urgent patching of actively exploited Zimbra flaw
BleepingComputer
Security Affairs
2026-08-21
The Hacker News
2026-08-20
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-26T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
23x
attribution
Attributing Entity
Russian Foreign Intelligence Service
authority
15x
timeline
Temporal Reference
October 2024
date
14x
organisation
Identified Entity
Cross-Site Scripting
entity
5x
source region
Origin Country
Russian Federation
country
3x
threat actor
APT Group
APT28
actor
3x
tactic
Cyber Operation Type
Remote Code Execution
tactic
3x
infrastructure
Zimbra Servers
270
zimbra servers
2x
target region
Target Country
Ukraine
country
2x
vulnerability
Exploited CVE
CVE-2026-73570
cve
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
Contextual Telemetry
Context Block
15 METRICS
industry
Targeted Sector
Government
sector
data breach
Zimbra Instances
270
zimbra instances
infrastructure
Software Version
10.1.20
version
general metric
Unpatched Instances
8,200
unpatched instances
general metric
Instances
274
instances
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Compromised Collaboration Suite
270
compromised collaboration suite
target region
Target Region
EUROPE
region
financial
Europe
4,382
europe
general metric
Asia
4,492
asia
general metric
Suite Entries
18
suite entries
general metric
Score
9
score
general metric
Aug
20
aug
general metric
Cve-2026
73,570
cve-2026
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.